The Neiman Marcus Group LLC
ent_019e2207df25768caed38e93ed5e6afc
Disclosures
9
State AG · 6 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
4,354,346
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- The Neiman Marcus Group LLC
- Normalized
- the neiman marcus— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 3LGBWM7SJ10PEV1KRW42
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (9)newest first
- 🍁Vermont State AGas victim2024-06-24
The Neiman Marcus Group notified consumers that an unauthorized third party accessed a database platform between April and May 2024. Affected data included names, contact info, DOB, and gift card numbers. Neiman Marcus disabled access, engaged cybersecurity experts, and notified law enforcement. No specific count of affected individuals was provided in the filing.
- 🦞Maine State AGas victim2024-06-24
The Neiman Marcus Group LLC reported an external system breach that occurred between April 14, 2024, and May 24, 2024, affecting 184 Maine residents. The breach was discovered on May 24, 2024, and affected individuals were notified on June 24, 2024.
- 🌲Washington State AGas victim2024-06-24
The Neiman Marcus Group LLC, a business sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2024-05-24 and filed notice on 2024-06-24. 11,049 Washington residents were affected. 31 days elapsed between awareness and notification. 40 days to identify the breach. 0 days to contain the breach.
- 🦞Maine State AGas victim2021-10-01
The Neiman Marcus Group, LLC reported an external system breach (hacking) occurring between May 2 and May 17, 2020, discovered on September 9, 2021. The incident affected 4,354,346 individuals in the U.S., including 5,951 Maine residents. Acquired data included names and financial account or credit/debit card numbers with security codes. Substitute notice was sent on September 30, 2021.
- 🐻California State AGas victim2021-09-30
In May 2020, an unauthorized party obtained personal information from Neiman Marcus Group customer online accounts. Affected data included names, contact information, payment card numbers and expiration dates (without CVV), virtual gift card numbers (without PIN), and online account credentials. The incident was discovered in early September 2021. NMG engaged a cybersecurity expert, notified law enforcement, and required password resets for affected accounts.
- 💎Delaware State AGas victim2021-09-30
The Neiman Marcus Group notified customers of a data breach involving unauthorized access to online account information in May 2020. Affected data included names, contact info, payment card numbers (no CVV), virtual gift card numbers, and usernames/passwords/security questions. The company engaged cybersecurity experts and law enforcement, and required password resets for affected accounts. The investigation was ongoing as of the September 30, 2021 notification.
- 🐻California State AGas victim2017-07-26
In January 2016, The Neiman Marcus Group detected unauthorized access to its mobile app environment via automated brute-force attacks using credentials stolen from other breaches. Attackers accessed customer names, addresses, phone numbers, last four digits of credit cards, expiration dates, and gift card account numbers. Full credit card numbers were not accessed. The company updated app security controls and required password resets for affected accounts.
- 🦬Montana State AGas victim2017-04-17
Neiman Marcus Group (NMG) reported a data breach to the Montana Attorney General. The breach was reported on 2017-04-17. The breach occurred from 12/26/2015 to 4/2/2017. 7 Montana residents were affected.
- 🐻California State AGas victim2017-04-14
The Neiman Marcus Group reported a data security breach to the California Attorney General. The incident occurred on December 26, 2015. The breach involved PCI (payment card industry) and PII (personally identifiable information) data, including identity basic information and financial account details. The specific attack vector, number of affected individuals, and discovery date are not disclosed in the provided summary or attachment text.